Win-LiFTImager is a USB based tool for First Responders, Investigators and IT Security Professionals to collect
volatile data, which will be lost once the computer system is shutdown.

Win-LiFTImager is a Forensic Volatile Data Acquisition tool. It can be used to acquire forensically
sound volatile data from a running system to a USB storage.Capture volatile artifacts such as Running Process List, System Information, User Details, Network Information,
Loaded Drivers List and Stored Passwords to investigate an incident.

There is a facility to select list of volatile artifacts to be acquired based on the cyber crime under investigation.Acquire full range of system memory. Dump the registry files by a file system level reading.